XRP Ledger's new proposal blocks the flash loan attacks costing DeFi hundreds of millions
XRPL’s draft AMM amendment says flash-loan attacks are impossible on the network, highlighting a built-in security edge as DeFi grows.
Intelligence analysis by GPT-5.4 Mini

A draft XRP Ledger amendment says flash-loan attacks cannot happen on XRPL because transactions are atomic but cannot make composable intra-transaction calls. The story frames that design choice as a security advantage, even as XRPL tries to close its DeFi gap with new AMM features and growing tokenized asset activity.
XRPL is like a vending machine that only lets a purchase finish if every step is valid. Because of that design, a certain kind of trick where someone borrows money, uses it to cause trouble, and pays it back all in one move cannot happen there.
On some other blockchains, that trick has been used to steal money from apps that were built poorly. The article says XRP Ledger avoids that risk by how its transactions work.
But there is a tradeoff. Some honest traders use the same fast-borrow idea to do useful jobs quickly, like swapping money or fixing prices. XRPL avoids the danger, but it also gives up those fast tricks.
Analysis
What the proposal says
A draft amendment on the XRPL standards repository would add concentrated liquidity and StableSwap-style pools to the chain’s native automated market maker. In the amendment’s security notes, the authors say flash-loan attacks are structurally impossible on XRPL because its transactions are atomic but do not allow composable calls within a single transaction.
Why that matters
The article explains the usual flash-loan pattern: a trader borrows funds with no collateral, uses them inside one transaction to manipulate a price or drain a weak pool, then repays before settlement. That pattern depends on being able to chain multiple actions together inside one transaction. XRPL’s transaction model does not allow that sequence, which removes the attack path entirely.
The tradeoff
That same limitation also blocks legitimate DeFi uses of flash loans. On Ethereum, flash loans help with arbitrage, liquidation bots, and collateral swaps. XRPL is giving up those capital-efficient tools in exchange for a narrower attack surface.
Bigger context
The piece notes that recent exploits at Thorchain, Drift, and KelpDAO relied on flash-loan mechanics, and that cross-chain bridges have lost more than $2.8 billion since 2021, according to Chainalysis. XRPL is now trying to expand beyond a small DeFi footprint, with tokenized real-world assets on the ledger said to have crossed $3 billion in total value. If the AMM amendment passes and liquidity grows, the network’s built-in exploit resistance could become part of its competitive pitch to institutional users.
Key points
- XRPL’s draft AMM amendment says flash-loan attacks are structurally impossible on the network.
- The reason is architectural: XRPL transactions are atomic but do not allow composable intra-transaction calls.
- The article links recent DeFi exploits at Thorchain, Drift, and KelpDAO to flash-loan mechanics.
- XRPL trades away legitimate flash-loan uses such as arbitrage and liquidations.
- Growing tokenized asset activity and planned AMM upgrades could make XRPL’s security model more relevant to institutions.



